{"id":47529,"date":"2020-09-03T16:37:26","date_gmt":"2020-09-03T22:37:26","guid":{"rendered":"https:\/\/jumpcloud.com\/?page_id=47529"},"modified":"2024-07-01T16:04:36","modified_gmt":"2024-07-01T20:04:36","slug":"vulnerability-disclosure-policy","status":"publish","type":"page","link":"https:\/\/jumpcloud.com\/vulnerability-disclosure-policy","title":{"rendered":"Vulnerability Disclosure Policy"},"content":{"rendered":"\n
JumpCloud is committed to protecting the privacy and security of our customers. Although we have taken every effort to minimize all the security bugs in our systems, we realize that something may have been missed. We encourage individual security researchers to study\/analyze our platform to make it even safer. Our Vulnerability Disclosure Program (VDP) is intended to minimize any security flaws found in our infrastructure and software. If you believe you have found a security vulnerability in our platform, please contact us as soon as possible. We will investigate all legitimate reports and do our best to address the issue quickly. Before reporting the issue, please take a moment to review this page, which includes our disclosure policy, guidelines, rules, the program\u2019s scope, rewards, and how to contact us.<\/p>\n\n\n\n
Participating in JumpCloud\u2019s VDP requires you to follow our guidelines. Please adhere to the following guidelines to be eligible for rewards under this disclosure program:<\/p>\n\n\n\n
Residents in U.S. sanctioned countries (Cuba, Iran, Sudan, Syria, and North Korea) are ineligible.<\/p>\n\n\n\n
The following services and domains are considered in scope:<\/p>\n\n\n\n
These specific endpoints and our endpoints are considered in scope:
<\/p>\n\n\n\n
Generally speaking, any bug that poses a significant vulnerability could be eligible for a reward. It is entirely at JumpCloud\u2019s discretion to decide whether a bug is significant enough to qualify for an award. Security issues that typically would be eligible (though not necessarily in all cases) include:<\/p>\n\n\n\n
Things that are not eligible for reward include:<\/p>\n\n\n\n
Send an email to vulnerability@jumpcloud.com<\/a><\/strong> using the PGP key located here, with information about the vulnerability and detailed steps on how to replicate it.<\/p>\n\n\n\n We will make every effort to respond to accurate reports within seven business days.<\/p>\n\n\n\n JumpCloud will utilize Bugcrowd’s VRT<\/a> for initial<\/strong> prioritization and review its overall impact for further prioritization based upon JumpCloud\u2019s Vulnerability Management Program.<\/p>\n\n\n\n All Assessments are considered final.<\/p>\n\n\n\n \n \n
\n -----BEGIN PGP PUBLIC KEY BLOCK-----
\n Version: PGP Universal 3.4.2 (Build 10531)
\n mQINBGRrjLwBEADi9Xm1ryJtXm4ut2PbIoJORbTXv5rkrg2KgUxhQyo2YNxp6mW1
\n RlIjxzJp71RESG2kP3K0oV2JofVFcAuKdB\/KNx5O72n7Cg2drr6xcBPJK3Lld5Q6
\n Bd54rGxUb3SMHrgXx+YvV1PzYIsz34mWQN\/2EwkeVpJ3rJGnyxnVPmzwixTBG3wH
\n sBRX84HIKNNJsii3xBsmNzpgKrlAhjJkXz3iNYP+gNdW56fLW272SyeiTvqkdZQK
\n uvoT04tWIteKF4+ETSbXjGQfqbCWdzwLmlPZASndVA9lT7IFVwWEVRvMKhSOMIcc
\n U6gkG0BuP\/ZDY3wZsMvF5iSSQyQZiaVRM9\/zoJlmTWMKFfzWm8cZx5utIzbNqTRi
\n 0vRf903DkR\/pZLoQIKEBKDd09tbGrSGFWO0t8cKhZ3\/eEc4KjBxmovV6SS2F5C1O
\n YqheJlGsXsM24ya5gt6HlMfuCDYGkZ\/LhzkQtDeTja+Olzd0s4kAT6rzpr0Gj4uu
\n NTirKeyVlb3LnWMYkvzNzHjI9iGgt1FIos2prJngEEfSt8Vod24upVpseN5RuplN
\n Y9k9k80+aoYQn+lJ6iFQ0Pk739mRZvxYC3mEgilbFScnF5efOgFD6EhWG\/pPw9ag
\n \/EB\/oSV8zbrsHBIn6SEwqyMuDf041b1t50Cwm8P5fFmd6vxLJzITXYwxaQARAQAB
\n tGhKdW1wQ2xvdWQgU2VjdXJpdHkgKGh0dHBzOi8vanVtcGNsb3VkLmNvbS92dWxu
\n ZXJhYmlsaXR5LWRpc2Nsb3N1cmUtcG9saWN5KSA8dnVsbmVyYWJpbGl0eUBqdW1w
\n Y2xvdWQuY29tPokCUQQTAQgAOxYhBBwGRsmrg96a+a1SI89nsno2xKqdBQJka4y8
\n AhsDBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJEM9nsno2xKqd7rEP\/RPQ
\n V56t+R3I64IU73UyHvtwifn286JTu9+K93nowW+UhOcj8WTIbQr66cpg5Z7\/gcR3
\n gQKdIXX3tfkLgdF+IC19eV\/rnh61Inw1CX2E36AMgHMFVlpuTgv6opJUbLFoQWo2
\n sxPkLo5LkWO54iLmVXALByvf6nmnYaPMFt7A\/xATrGnJbBG9pXxO5IR3hJ3wO+oD
\n vwm1zLSwTxWq\/v7QhLzIPfJ8A5GZBTtn9nCrK4jXY\/69VY94MdSE7p\/cAYSEX38k
\n HGzGGcROBAYjjw2D2VVKRE7Eultvt9V6SbDrQHLA1SVoOrOc\/FwxQDonoyqScpvt
\n a4WeocFD1exR50aHTKmXm2rdUeiyDsBFgQ4kSMmuYIuUzqJAQiyCSIK6pzk5VT0i
\n wwrD37n9m\/cZg2tWnIHgR9JxW3Z5sr7T2MiRlNqQc7NhmOe0W6SdNLmPeyqG4QF3
\n 9V6dayYOjM3wjvUfTPhLh8yEtJEXAOtxjCx8VCU6ptTf6QJe\/G3WmWs8me1MexbQ
\n qN3vgmWJ2tCloNoLq3G1N9XEb0c1lqiTTSeNnlXCSVTXXd0vO6VXgDjfEowpaA2G
\n T6F1kgBkx4CkT\/pKaacWUvCPTutj0Tjm0+lKOKGuYTp2Vr3ixNb2KBoAin\/nVNDA
\n 482CZt+UHElFZJC0cIa8SRdBiJH6kgFdykSx56mAiQEiBBABCAAMBQJka5xOBQMA
\n EnUAAAoJEJcQuJvKV618BxAH\/RDHiH1dvQ8AlVwYzyFK+5\/KUxfxSRzjoNol7glw
\n f3rk0+uV6mHEp7HO6xkSy4iSrgdVl4Y\/ExhPhohBMdwWrtNM71WYWADlaPcScrLW
\n 759qrg6tJL\/hnN0V7PR8YD\/Tf2YgyJp9k8Q1Ztpfzlh\/DBXnxYEzrRy\/e\/xnN1sF
\n y1ZC+YtcQK2QNyEPJuFevdo\/GtAUek+IB1ppEYHgJkwGwLPy0fdIoXAp5tILohF+
\n nsH1bZ4\/SRC6A7lFnjDGtpBwWyjKp61Yjr9lV\/TEkp\/B8npbl\/UTxbS7I8629g+n
\n vSaAdhTqhurjQld76Ow1H5Z4IeVhSllgWBipKswclyZEFM+5Ag0EZGuMvAEQANdM
\n 6O239URzbr571R68XwJoIhOxuz9xtPYiehLmlwY6tjcBRoLLb03TRcBajjWVHrhG
\n aE+GQZkiyt0JCI0fS0GeQfcmWCuqKQbDT8GG1LYbR+Q0GoDyiiC1oeBW5eSJrIav
\n Cnfw7GqcTKJydN1cDmhBk9wzABbpP9NK74wgrcY00PNQbixHxFWNKsgVezqORSBZ
\n ej4SQol0OeDzdrXLXF\/oG75GwOvfoQcIvVtR4nsbJHyjuc9j0uQb7SooKn0p4q2P
\n b8dVqVjHeImI3SVij5Lyf5Gvf3ABy8CWO0KNJENAQCyn+dj9IvZM7HCj8IOZ6YWO
\n ZqZIpxkENRAR7BFVliO0C\/lJeI2PuGnFzOguycBGgaVOR627FGn6iLg5V71nHCc4
\n Z77or7+nuUe3Q\/VM7+AGvmntbXi4c15Jxtaqj9eGfCcHlSCoa7YaG3Vmlzcee9xg
\n X4\/iSK0rpVjMGNY3b6HsRa6kHlv\/Dno+FFBzNloKk2OdjyOMZDebZKDcgkgsIDbk
\n GdWGhbbkt16r8A5yqfZ1+5P7blEzHxdEyOuzhAdn8smtP8Odgx5uJHsNk8twSwl0
\n GIe6jPHWtmEahN3mpYzB6mb7fLWoschA3lW5pG9QeCkF3g5\/hxoTUJU1oX2Ck7Xv
\n 2RrRSY51SJL4NWJiR\/eOvec3VOyDCdN1Br32ybpxABEBAAGJAjYEGAEIACAWIQQc
\n BkbJq4PemvmtUiPPZ7J6NsSqnQUCZGuMvAIbDAAKCRDPZ7J6NsSqndm5EACh+Xay
\n qL+n64ajKuSjQpvSA0T8Dk1pDYMeKBZgfFL1zQPid272nttugG6Nlksc+MvL+4KH
\n oKX+T7c1g9kJRNeOTIM2Epaiu\/xEwUPacqLI6sx5pL5rEbUq\/iT+T5o3DuQ1pPE4
\n uaHbyx3K1\/cxuDu9VMOpUwhUpXeBCy+WL4e0N7NOwKYF7A++Z1rI5\/9HE2lwwY\/0
\n 9ctC5YIjfK4u7hmJe2ts0N\/jjHJpeK+hSuk3KoncphvdGYnj2nVgW3eg06CuDcq5
\n jfo1+afdBRxIQN84oI5lizNYoTHPxiIh2Ob0ZZ5ZsoT6lvQ+z4h0pacYiQHkKPFR
\n nSIOedI4DO4fKM9DkYnHQ10pDyG4BgIxkTWdN0vKXG0le3Hw5kgTlyJtb0u7Dg1W
\n Au\/nRgYu0UtDRPLa\/ca0Gp7kkPKsJ5zvTZPTeSFThpfuerPb94WUtXA4X9CV\/DhP
\n U2KwNHI\/dUdJx7EVEcSWdONsQPe7fPPlxTXM5CBe5tqhKvi01CBiXky\/aoR1RKzC
\n iM1pgPXkUlQG4CGy8XkEDrJh1SmNdH0xX1AW4srlokUbefeHfzY7hxAg\/DxKZKSH
\n ZsidiSHmAG26BXpUs5N3F1qBiurao9FChNCKlcTe8ecEQRQOiLeT7ZfQnSA0y5dm
\n D3UCBlrzO1aKp50ptQ3NCyP8Lz1eG\/ixb3LvOA==
\n =Gqmu
\n -----END PGP PUBLIC KEY BLOCK-----\n <\/code>\n <\/p>\n <\/div>\n <\/div>\n<\/div> \n<\/div>\n<\/div>\n\n\n\nRatings\/Rewards<\/h1>\n\n\n\n
Ratings<\/h2>\n\n\n\n